Active cPanel/WHM zero-day exploit prompts rapid patch after PoC release

1 min read
Source: BleepingComputer
Active cPanel/WHM zero-day exploit prompts rapid patch after PoC release
Photo: BleepingComputer
TL;DR Summary

A critical authentication-bypass vulnerability CVE-2026-41940 in cPanel/WHM and WP Squared is being actively exploited in the wild; recent technical details and a PoC show CRLF injection in login/session handling that can grant control without a password. cPanel issued a patch on April 28, while mitigations include restarting cpsrvd, blocking ports 2083/2087/2095/2096 if patching isn’t immediate, and using provided detection scripts to verify compromise.

Share this article

Reading Insights

Total Reads

0

Unique Readers

5

Time Saved

4 min

vs 5 min read

Condensed

93%

85263 words

Want the full story? Read the original article

Read on BleepingComputer